Auditen
Home / Frameworks / NIST CSF 2.0 / Organizational profiles: current versus target

Organizational profiles: current versus target

Organizational Profiles require a company to document its current cybersecurity posture and define its desired future state using the NIST CSF Core. By comparing the "Current Profile" against the "Target Profile," an organization identifies security gaps to prioritize investments and risk reduction efforts.

What it means

In practice, this is a gap analysis exercise. The Current Profile acts as a baseline, detailing which cybersecurity outcomes are already being achieved and how they are implemented based on existing policies, tools, and processes. It provides a realistic snapshot of the organization's present security maturity.

The Target Profile represents the "ideal state" that aligns with the organization's risk appetite, business objectives, and legal or regulatory obligations. It does not necessarily mean implementing every single subcategory in the Framework, but rather selecting those that are most critical to the specific mission of the organization.

The difference between these two profiles creates a roadmap. This process transforms the NIST CSF from a static list of suggestions into a customized strategic plan for improving cybersecurity resilience over time.

How to meet it

Evidence an auditor asks for

  • A completed Current Profile document (often a spreadsheet) mapping existing capabilities to CSF subcategories.
  • A documented Target Profile that justifies why specific outcomes were prioritized based on risk appetite.
  • A Gap Analysis report explicitly detailing the deficiencies between the current and target states.
  • A strategic roadmap or Project Plan showing scheduled improvements designed to close those identified gaps.

Common pitfalls

  • Aiming for "perfection" by setting a Target Profile that requires every single CSF subcategory, resulting in an unfunded and unrealistic goal.
  • Treating profiles as one-time checkboxes rather than living documents that evolve with the threat landscape.
  • Creating a Target Profile without input from business leadership, leading to security goals that conflict with operational needs.